OpenVLAN vs HashiCorp Boundary

Both kill standing credentials. One brokers sessions to hosts; the other builds the network the hosts live on.

Side by side

OpenVLANBoundary
ModelNetwork layer — any connection, any protocolSession broker for SSH/DB/HTTP
Self-serve app accessUsers connect directly to allowed servicesThrough broker each time
Non-brokered protocols (RDP, custom TCP)First-classLimited / via workers
Infrastructure to runNone (SaaS control plane)Controllers + workers (or HCP-managed)
Session recordingBuilt in (SSH)Session/credential monitoring
Whole-network use (DNS, Taildrop, k8s)NativeOut of scope
IaC ergonomicsTerraform provider + ACLs as codeTerraform-native

Where each wins

Choose Boundary when…

You live in HashiCorp land, need strict broker-style access to specific hosts, and already operate Vault for credentials.

Choose OpenVLAN when…

You want one network for everything — access control included — without running brokers, workers, or per-protocol gateways.

Access control without a broker tax